CVE-2026-82477

Summary

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.

Affected Software

VendorProductVersion RangeStatus
MITREHeimdall2.11.6 < 2.14.0affected

Weaknesses

  • CWE-918: CWE-918 Server-Side Request Forgery (SSRF)

References